kernel: execve: must clear current->clear_child_tid
Published Aug 18, 2009
5.9
MEDIUMCVSS 2.0
EPSS 0.52%
Description
The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.
Affected products
No data.
Configuration 1
- ≤ 2.6.29.5
- 2.6.30
- 2.6.30
- 2.6.30
- 2.6.30
- 2.6.30
- 2.6.30
- 2.6.30
Configuration 2
- 9
- 11.0
- 10
- 9
- 10
Configuration 3
- 11
Configuration 4
- 6.06
- 8.04
- 8.10
- 9.04
Configuration 5
- 3.0
- 5.0
- 3.0
- 5.0
- 3.0
- 5.0
Configuration 7
Running on/with
- 5.0
No data.
MRG for RHEL-5
kernel-rt-0:2.6.24.7-132.el5rt
Fixed · RHSA-2009:1239
Red Hat Enterprise Linux 3
kernel-0:2.4.21-63.EL
Fixed · RHSA-2009:1550
Red Hat Enterprise Linux 4
kernel-0:2.6.9-89.0.11.EL
Fixed · RHSA-2009:1438
Red Hat Enterprise Linux 5
kernel-0:2.6.18-164.el5
Fixed · RHSA-2009:1243
Red Hat Enterprise Linux 5.3.Z - Server Only
kernel-0:2.6.18-128.8.1.el5
Fixed · RHSA-2009:1466
| Product | Package | State | Advisory |
|---|---|---|---|
| MRG for RHEL-5 | kernel-rt-0:2.6.24.7-132.el5rt | Fixed | RHSA-2009:1239 |
| Red Hat Enterprise Linux 3 | kernel-0:2.4.21-63.EL | Fixed | RHSA-2009:1550 |
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-89.0.11.EL | Fixed | RHSA-2009:1438 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-164.el5 | Fixed | RHSA-2009:1243 |
| Red Hat Enterprise Linux 5.3.Z - Server Only | kernel-0:2.6.18-128.8.1.el5 | Fixed | RHSA-2009:1466 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:P/I:P/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.52% (0.00516) | 41.80th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.52% (0.00516) | 39.61th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.09% (0.00086) | 22.57th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00052) | 22.07th | v3 (v2023.03.01) |
| Jun 13, 2024 | 0.05% (0.00052) | 20.16th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00052) | 18.13th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
References (30)
- http://article.gmane.org/gmane.linux.kernel/871942 mailing-listx_refsource_MLISTBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00007.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2009-1243.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://secunia.com/advisories/35983 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/36501 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/36562 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/36759 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/37105 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/37351 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/37471 third-party-advisoryx_refsource_SECUNIABroken Link
- http://www.openwall.com/lists/oss-security/2009/08/04/2 mailing-listx_refsource_MLISTExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2009/08/05/10 mailing-listx_refsource_MLISTExploitMailing ListThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1438.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/archive/1/507985/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/512019/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-852-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2009-0016.html x_refsource_CONFIRMThird Party Advisory
- http://www.vupen.com/english/advisories/2009/3316 vdb-entryx_refsource_VUPENBroken Link
- https://access.redhat.com/security/cve/CVE-2009-2848 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=515423 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52899 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2009-2848
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11412 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8598 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9766 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2009-1550.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2009-2848
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01256.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
Change history (0)
No recorded changes yet.